CVE-2024-0217

A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost.
Configurations

Configuration 1 (hide)

cpe:2.3:a:packagekit_project:packagekit:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

History

21 Nov 2024, 08:46

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2024-0217 - Mitigation, Third Party Advisory () https://access.redhat.com/security/cve/CVE-2024-0217 - Mitigation, Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2256624 - Issue Tracking, Patch, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2256624 - Issue Tracking, Patch, Third Party Advisory
References () https://github.com/PackageKit/PackageKit/commit/64278c9127e3333342b56ead99556161f7e86f79 - Patch () https://github.com/PackageKit/PackageKit/commit/64278c9127e3333342b56ead99556161f7e86f79 - Patch

02 Feb 2024, 15:20

Type Values Removed Values Added
CPE cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
First Time Fedoraproject
Fedoraproject fedora
References () https://github.com/PackageKit/PackageKit/commit/64278c9127e3333342b56ead99556161f7e86f79 - () https://github.com/PackageKit/PackageKit/commit/64278c9127e3333342b56ead99556161f7e86f79 - Patch

25 Jan 2024, 16:15

Type Values Removed Values Added
References
  • () https://github.com/PackageKit/PackageKit/commit/64278c9127e3333342b56ead99556161f7e86f79 -

10 Jan 2024, 18:10

Type Values Removed Values Added
First Time Packagekit Project packagekit
Packagekit Project
Redhat enterprise Linux
Redhat
CPE cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:packagekit_project:packagekit:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Summary
  • (es) Se encontró un fallo de use after free en PackageKitd. En algunas condiciones, el orden de los mecanismos de limpieza de una transacción podría verse afectado. Como resultado, podría producirse cierto acceso a la memoria en regiones de memoria que se liberaron previamente. Una vez liberada, una región de memoria se puede reutilizar para otras asignaciones y cualquier dato previamente almacenado en esta región de memoria se considera perdido.
References () https://access.redhat.com/security/cve/CVE-2024-0217 - () https://access.redhat.com/security/cve/CVE-2024-0217 - Mitigation, Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2256624 - () https://bugzilla.redhat.com/show_bug.cgi?id=2256624 - Issue Tracking, Patch, Third Party Advisory

03 Jan 2024, 17:26

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-03 17:15

Updated : 2024-11-21 08:46


NVD link : CVE-2024-0217

Mitre link : CVE-2024-0217

CVE.ORG link : CVE-2024-0217


JSON object : View

Products Affected

redhat

  • enterprise_linux

packagekit_project

  • packagekit

fedoraproject

  • fedora
CWE
CWE-416

Use After Free